Malware

About “Symmi.91423” infection

Malware Removal

The Symmi.91423 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.91423 virus can do?

  • Executable code extraction
  • Starts servers listening on 0.0.0.0:3000, 0.0.0.0:3001, 0.0.0.0:259, 0.0.0.0:3002
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Anomalous binary characteristics

How to determine Symmi.91423?


File Info:

crc32: AF3DF94D
md5: 311d12aae6191924586dc902f07574cd
name: 311D12AAE6191924586DC902F07574CD.mlw
sha1: 2443411fda2005c44336a0639d49aee8efd5d425
sha256: e2adfe663bf9e713ca66f4460961bbd76e674112f3640527ac98036ebb9af757
sha512: e840001e23bde3ac4655bc55c4265d013e84fc46cf2916372407c7b99efb77509491fa16ed8f54e9c8f58e0ea07c9659e0626fcad9f89e68c34081c9a1e9d9a1
ssdeep: 24576:eh8CSYaxYdo9cDXtymS2AYmHAJGKdLqRy4fQVW8R:ehXVO9cXtymSHrRzsfR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x5f52x4f5cx8005x6240x6709
FileVersion: 1.0.0.0
CompanyName: x7693
Comments: x670dx52a1x7aef
ProductName: x670dx52a1x7aef
ProductVersion: 1.0.0.0
FileDescription: x670dx52a1x7aef
Translation: 0x0804 0x04b0

Symmi.91423 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.91423
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.ae6191
CyrenW32/QQPass.AD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
ZonerTrojan.Win32.92118
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Flystudio-6937682-0
BitDefenderGen:Variant.Symmi.91423
MicroWorld-eScanGen:Variant.Symmi.91423
Ad-AwareGen:Variant.Symmi.91423
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.pkd@1qu9um
BitDefenderThetaGen:NN.ZexaCO.34790.6u3@a4J7x!gb
VIPREBackdoor.Win32.FlyAgent.h (v)
McAfee-GW-EditionBehavesLike.Win32.Autorun.dc
FireEyeGeneric.mg.311d12aae6191924
EmsisoftGen:Variant.Symmi.91423 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.FB
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
GridinsoftMalware.Win32.Gen.bot!se24374
GDataWin32.Trojan.FlyStudio.A
Acronissuspicious
McAfeeArtemis!311D12AAE619
MAXmalware (ai score=82)
VBA32Trojan.Bitrep
MalwarebytesTrojan.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R005H0CG321
RisingTrojan.Generic@ML.100 (RDML:VgcIonhtT2qBf4eTzOPgFw)
IkarusTrojan.Bluteal
MaxSecureTrojan.Autorun.DM
FortinetW32/Generic.AP.14793D8!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Symmi.91423?

Symmi.91423 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment